mcp-troubleshoot
Warn
Audited by Snyk on Feb 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The skill instructs running "npx @gongrzhe/server-gmail-autoauth-mcp auth", which causes npx to fetch and execute remote npm package code at runtime and is presented as the required re-authentication step for Gmail MCP (package: @gongrzhe/server-gmail-autoauth-mcp), so this external dependency executes remote code during runtime.
Audit Metadata